誰在線上

正在瀏覽這個版面的使用者: 沒有註冊會員 和 12 位訪客

要偷一條友既 iTunes password,其實唔難

歡迎各位影音 fans 齊齊吹水

要偷一條友既 iTunes password,其實唔難

文章發表人 mtr 發表於 2017-10-10, 22:31

https://krausefx.com/blog/ios-privacy-s ... -by-asking



... iOS asks the user for their iTunes password for many reasons, the most common ones are recently installed iOS operating system updates, or iOS apps that are stuck during installation.

As a result, users are trained to just enter their Apple ID password whenever iOS prompts you to do so. However, those popups are not only shown on the lock screen, and the home screen, but also inside random apps, e.g. when they want to access iCloud, GameCenter or In-App-Purchases.

This could easily be abused by any app, just by showing an UIAlertController, that looks exactly like the system dialog.

Even users who know a lot about technology have a hard time detecting that those alerts are phishing attacks.


How can you protect yourself

- Hit the home button, and see if the app quits:
If it closes the app, and with it the dialog, then this was a phishing attack

- If the dialog and the app are still visible, then it's a system dialog. The reason for that is that the system dialogs run on a different process, and not as part of any iOS app.

- Don't enter your credentials into a popup, instead, dismiss it, and open the Settings app manually. This is the same concept, like you should never click on links on emails, but instead open the website manually

- If you hit the Cancel button on a dialog, the app still gets access to the content of the password field. Even after entering the first characters, the app probably already has your password.


Initially I thought, faking those alerts requires the app developer to know your email. Turns out, some of those auth popups don't include the email address, making it even easier for phishing apps to ask for the password.
圖檔
mtr
Fun區守護神 - 變淫大金剛
Fun區守護神 - 變淫大金剛
  頭像
 
文章: 53287

註冊時間:
2007-04-17, 19:21

Re: 要偷一條友既 iTunes password,其實唔難

文章發表人 peterso 發表於 2017-10-11, 00:24

:coldsweat2: :coldsweat2: :coldsweat2:
圖檔圖檔圖檔
圖檔圖檔圖檔
peterso
Fun區正義聯盟 - 冇雀隊長
Fun區正義聯盟 - 冇雀隊長
  頭像
 
文章: 175499
來自: 肛門隔離

註冊時間:
2004-11-16, 18:33


回到 影音 fun 區